GHSA-wvpg-4wrh-5889
PrestaShop Checkout Target PayPal merchant account hijacking from backoffice
Quick fix
GHSA-wvpg-4wrh-5889 — prestashop/ps_checkout: upgrade to the fixed version with the command below.
composer require prestashop/ps_checkout:^4.4.1Details
### Impact Wrong usage of the PHP `array_search()` allows bypass of validation.
### Patches The problem has been patched in versions: - v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1) - v4.4.1 for PrestaShop 8 (build number: 8.4.4.1) - v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5) - v5.0.5 for PrestaShop 8 (build number: 8.5.0.5) - v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)
Read the [Versioning policy](https://github.com/PrestaShopCorp/ps_checkout/wiki/Versioning) to learn more about the build number.
### Credits [Léo CUNÉAZ](https://github.com/inem0o) reported this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.4.1composer require prestashop/ps_checkout:^4.4.15.0.0Fixed in: 5.0.5composer require prestashop/ps_checkout:^5.0.5